Splunk Search

timechart limit=0 useother=false span=2d count by serviceとしたとき、serviceごとに2日分の合計がされてしまう。

TomohikoHoshino
Observer

Splunk search headで以下のクエリとした場合、service毎に2日ごとに合計量が表示されてしまいます。

timechart limit=0 useother=false span=2d count by service

 

2日おきに、集計計日のみの合計量を出したいのですが、どのようなクエリになりますでしょうか?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...